← Back to home

Dutchess Community CollegeHigher Education

EIN: 146012314

UEI: VFW3KAT2NVJ3

Audited by: Bonadio & Co., LLP

Oversight agency: 84 [Department of Education]

View federal awards & risk assessment →

Data as of August 31, 2026

Dutchess Community College10 audit years3 findings1 repeat
10
Audit Years
3
Total Findings
1
Repeat Findings
$18M
Federal Awards Expended (FY 2025)

FY 2025-08-31

LOW-RISK AUDITEE$18,019,631 federal awards expendedNo findings recorded this year

Management decision deadline — for entities that funded this organization

The FAC accepted this audit on April 1, 2026. Under 2 CFR 200.521(d), a pass-through entity that provided federal funds to this organization for this audit period must issue a management decision on these findings by October 1, 2026 (30 days from today).

What is a management decision? →

FY 2024-08-31

LOW-RISK AUDITEE$15,361,558 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 6, 2025 — management decision was due September 6, 2025.

FY 2023-08-31

LOW-RISK AUDITEE$14,758,771 federal awards expended

FAC accepted this audit on May 3, 2024 — management decision was due November 3, 2024.

2023-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCY

During our testing, we noted the following: While the IT Systems Team is the assigned resource for information security matters, the College communicated that it does not have a single qualified individual designated with the responsibility for implementing and enforcing the College’s information security program.  An annual IT risk assessment was not performed.  A vendor management program is not in place.  Mobile device management is not in place.  Backup media is not encrypted.  A full set of policies and procedures is not in place. Finding Reference: 2023-001 (Continued) U.S. Department of Education Student Financial Aid Cluster: Federal Supplemental Educational Opportunity Grants (Assistance Listing #84.007) Federal Work-Study Program (Assistance Listing #84.033) Federal Pell Grant Program (Assistance Listing #84.063) Federal Direct Student Loans (Assistance Listing #84.268) Compliance Requirement: Special Tests and Provisions Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor’s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College agrees with the findings and is in process of developing a corrective action plan to address. In addition, the College has made it a top priority to hire both a Chief Information Officer and a Chief Information Security Officer but has experienced difficulty getting a qualified pool of candidates.

Show full finding ▾
Full finding narrative

Finding Reference: 2023-001 U.S. Department of Education Student Financial Aid Cluster: Federal Supplemental Educational Opportunity Grants (Assistance Listing #84.007) Federal Work-Study Program (Assistance Listing #84.033) Federal Pell Grant Program (Assistance Listing #84.063) Federal Direct Student Loans (Assistance Listing #84.268) Nursing Student Loans (Assistance Listing #93.364) Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires the College, on an annual basis, to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer (student) information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, the GLBA risk assessment should include consideration of risk in each relevant area of operations, including:  Employee training and management.  Information systems, including network and software design, as well as information processing, storage, transmission, and disposal.  Detecting, preventing, and responding to attacks, intrusions, or other system failures. Condition: During our testing, we noted the following: While the IT Systems Team is the assigned resource for information security matters, the College communicated that it does not have a single qualified individual designated with the responsibility for implementing and enforcing the College’s information security program.  An annual IT risk assessment was not performed.  A vendor management program is not in place.  Mobile device management is not in place.  Backup media is not encrypted.  A full set of policies and procedures is not in place. Finding Reference: 2023-001 (Continued) U.S. Department of Education Student Financial Aid Cluster: Federal Supplemental Educational Opportunity Grants (Assistance Listing #84.007) Federal Work-Study Program (Assistance Listing #84.033) Federal Pell Grant Program (Assistance Listing #84.063) Federal Direct Student Loans (Assistance Listing #84.268) Compliance Requirement: Special Tests and Provisions Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor’s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College agrees with the findings and is in process of developing a corrective action plan to address. In addition, the College has made it a top priority to hire both a Chief Information Officer and a Chief Information Security Officer but has experienced difficulty getting a qualified pool of candidates.

Corrective Action Plan

CORRECTIVE ACTION PLAN Federal Award Findings and Questioned Costs Finding 2023-001 Student Financial Aid Cluster: Assistance Listing #84.007 Federal Supplemental Educational Opportunity Grants Assistance Listing #84.033 Federal Work-Study Program Assistance Listing #84.063 Federal Pell Grant Program Assistance Listing #84.268 Federal Direct Student Loans Assistance Listing #93.364 Nursing Student Loans Federal agency – U.S. Department of Education Grant Period – Year ended August 31, 2023 Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires the College, on an annual basis, to identify reasonably foreseeable internal and external risks to the security, confidentiality, and integrity of customer (student) information that could result in the unauthorized disclosure, misuse, alteration, destruction, or other compromise of such information, and assess the sufficiency of any safeguards in place to control these risks. At a minimum, the GLBA risk assessment should include consideration of risk in each relevant area of operations, including: Employee training and management. Information systems, including network and software design, as well as information processing, storage, transmission, and disposal. Detecting, preventing, and responding to attacks, intrusions, or other system failures. Condition: During our testing, we noted the following: While the IT Systems Team is the assigned resource for information security matters, the College communicated that it does not have a single qualified individual designated with the responsibility for implementing and enforcing the College’s information security program. An annual IT risk assessment was not performed. A vendor management program is not in place. Mobile device management is not in place. Backup media is not encrypted. A full set of policies and procedures is not in place. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. Contact Person Responsible for Corrective Action Plan: Donna Rocap, Associate Vice President of Administration Corrective Action Plan: The College agrees with the findings and is in process of developing a corrective action plan to address. In addition, the College has made it a top priority to hire both a Chief Information Officer and a Chief Information Security Officer but has experienced difficulty getting a qualified pool of candidates. Timing of Planned Corrective Action: The College expects to resolve this finding during its August 31, 2024 fiscal year.

About Special Tests and Provisions →

FY 2022-08-31

LOW-RISK AUDITEE$23,592,075 federal awards expendedNo findings recorded this year

FAC accepted this audit on April 30, 2023 — management decision was due October 30, 2023.

FY 2021-08-31

LOW-RISK AUDITEE$23,171,349 federal awards expendedNo findings recorded this year

FAC accepted this audit on May 22, 2022 — management decision was due November 22, 2022.

FY 2020-08-31

LOW-RISK AUDITEE$16,457,245 federal awards expended

FAC accepted this audit on May 27, 2021 — management decision was due November 27, 2021.

2020-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCYREPEAT OF 2019-001OTHER MATTERS

The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors.

Show full finding ▾
Full finding narrative

Finding 2019-001 (Repeat Finding) Student Financial Aid Cluster ? CFDA Numbers - 84.007, 84.033, 84.063, 84.268 Federal Agency ? U.S. Department of Education; Grant Period ? Year ended August 31, 2020; Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors.

Corrective Action Plan

U.S. Department of Education Student Financial Aid Cluster: CFDA 84.007 Federal Supplemental Educational Opportunity Grants CFDA 84.033 Federal Work-Study Program CFDA 84.063 Federal Pell Grant CFDA 84.268 Federal Direct Student Loans Federal agency ? U.S. Department of Education Grant Period ? Year ended August 31, 2020 Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition and Effect: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. Contact Person Responsible for Corrective Action Plan: Provost View of responsible officials: The College is currently in the process of developing the procedures and controls recommended by the auditors.

Prior Finding References

2019-001

About Special Tests and Provisions →

FY 2019-08-31

LOW-RISK AUDITEE$18,697,253 federal awards expended

FAC accepted this audit on May 25, 2020 — management decision was due November 25, 2020.

2019-001
Special Tests & Provisions
SIGNIFICANT DEFICIENCYOTHER MATTERS

The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors. The process is expected to require several months to complete.

Show full finding ▾
Full finding narrative

Finding 2019-001 Student Financial Aid Cluster ? CFDA Numbers - 84.007, 84.033, 84.063, 84.268; Federal Agency ? U.S. Department of Education; Grant Period ? Year ended August 31, 2019; Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Auditor?s Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. View of Responsible Officials: The College is currently in the process of developing the procedures and controls recommended by the auditors. The process is expected to require several months to complete.

Corrective Action Plan

Student Financial Aid Cluster: CFDA 84.007 Federal Supplemental Educational Opportunity Grants CFDA 84.033 Federal Work-Study Program CFDA 84.063 Federal Pell Grant CFDA 84.268 Federal Direct Student Loans Federal agency ? U.S. Department of Education Grant Period ? Year ended August 31, 2019 Compliance Requirement: Special Tests and Provisions Criteria: The Gramm-Leach-Bliley Act (Public Law 106-102) (GLBA) requires financial institutions to explain their information sharing practices to their customers and to safeguard sensitive data. The Federal Trade Commission considers institutions that participate in Title IV Educational Assistance to be financial institutions and subject to GLBA. This finding is based on the requirements for educational institutions participating in the federal awards and education loan program to meet the Federal Trade Commission?s GLBA Safeguards Rule (Title 16, Chapter I, Subchapter C, Part 314). Condition and Effect: The College has performed a high-level assessment for a number of common information security controls. However, the assessment lacks the expected risk assessment framework and scoring of risk likelihood and impact for all in scope systems, vendors, and data sets. Cause: The expected documentation supporting the required controls to adequately confirm compliance with GLBA safeguards was not complete. Effect: Without demonstrable, documented controls supporting compliance with the GLBA standards for safeguarding the protected data, compliance with the law and the requirements in the federal PPA may not be assured. Context: Inquiry and observation of the information received from the College related to compliance with GLBA. Recommendation: The College should review the GLBA safeguarding rules and as soon as practical implement and document the controls necessary for compliance with the rule, focusing on the completion of a documented, thorough, and standardized risk assessment and management reporting framework. The College should perform comprehensive risk assessments on a regular basis, which is suggested to be at least annually, and at any significant change in infrastructure or business process. Contact Person Responsible for Corrective Action Plan: Provost View of responsible officials: The College is currently in the process of developing the procedures and controls recommended by the auditors. The process is expected to be completed by August 31, 2020.

About Special Tests and Provisions →

FY 2018-08-31

LOW-RISK AUDITEE$17,210,454 federal awards expendedNo findings recorded this year

FAC accepted this audit on February 27, 2019 — management decision was due August 27, 2019.

FY 2017-08-31

LOW-RISK AUDITEE$17,699,197 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 4, 2018 — management decision was due September 4, 2018.

FY 2016-08-31

LOW-RISK AUDITEE$19,775,554 federal awards expendedNo findings recorded this year

FAC accepted this audit on March 15, 2017 — management decision was due September 15, 2017.

Data source: This information comes from the Federal Audit Clearinghouse, the official repository of Single Audit data. All data is public domain. Verify this organization's audit history at fac.gov.

Browse other Single Audit organizations in New York

Are you this organization?

Track your findings and corrective action plans across audit cycles.

Start tracking findings →

Do you fund this organization?

Monitor subrecipient audit findings and filing records.

Start monitoring →

Product

Resources

Legal

Single Audit Intelligence is an independent tool powered by Federal Audit Clearinghouse data. Not affiliated with GSA, OMB, or any federal agency.

© 2026 Single Audit Intelligence. All data is public domain.